This package contains the Corosync Cluster Engine Executive, several default APIs and libraries, default configuration files, and an init script.
Security Fix(es):
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents. This vulnerability affects Corosync when running in totemudp/totemudpu mode, which is the default configuration.(CVE-2026-35091)
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.(CVE-2026-35092)
{
"severity": "High"
}{
"aarch64": [
"corosync-3.1.8-8.oe2403sp1.aarch64.rpm",
"corosync-debuginfo-3.1.8-8.oe2403sp1.aarch64.rpm",
"corosync-debugsource-3.1.8-8.oe2403sp1.aarch64.rpm",
"corosync-vqsim-3.1.8-8.oe2403sp1.aarch64.rpm",
"corosynclib-3.1.8-8.oe2403sp1.aarch64.rpm",
"corosynclib-devel-3.1.8-8.oe2403sp1.aarch64.rpm"
],
"src": [
"corosync-3.1.8-8.oe2403sp1.src.rpm"
],
"x86_64": [
"corosync-3.1.8-8.oe2403sp1.x86_64.rpm",
"corosync-debuginfo-3.1.8-8.oe2403sp1.x86_64.rpm",
"corosync-debugsource-3.1.8-8.oe2403sp1.x86_64.rpm",
"corosync-vqsim-3.1.8-8.oe2403sp1.x86_64.rpm",
"corosynclib-3.1.8-8.oe2403sp1.x86_64.rpm",
"corosynclib-devel-3.1.8-8.oe2403sp1.x86_64.rpm"
]
}